Original | Odaily Planet Daily (@OdailyChina)

Author | Azuma (@azuma_eth)

AI has once again made astonishing progress in mathematics.

On the morning of October 7, Beijing time, OpenAI announced a series of mathematical results produced by its internal frontier models. The work was ultimately compiled on GitHub into 722 manuscripts and 372 families of results, spanning number theory, geometry, combinatorics, theoretical computer science, and other fields. Among them were important mathematical topics such as the Milne rationality conjecture and algebraic specialization, the quasi-Riemann hypothesis, and Hilbert’s tenth problem. OpenAI revealed that approximately 4,000 questions were posed to the models during the evaluation, with each result using, on average, an amount of compute equivalent to about three hours of ChatGPT Pro thinking.

That same evening, Justin Drake, an Ethereum Foundation researcher and technical luminary, issued a rather radical call to action: the crypto industry should begin calmly planning for “bunker mode”—gradually moving assets to new addresses that have never signed a transaction.

Drake’s reasoning is straightforward: AI’s frighteningly rapid progress in mathematical ability could break the Elliptic Curve Digital Signature Algorithm (ECDSA) before quantum computing is truly mature, directly threatening the security of accounts on major blockchains such as Bitcoin and Ethereum.

ECDSA and “Bunker Mode”

For a long time, the crypto industry has focused its account-security defenses on the distant “Q-day” (the day quantum computers break modern public-key cryptography). But Drake’s warning this time is that the mathematical superintelligence brought by AI could sentence ECDSA to death on classical computing hardware, well ahead of schedule. The timeline for this risk can no longer simply be measured in “decades from now”: even the most pessimistic scenarios could unfold within months or years. An attacker might only need access to a large GPU cluster to recover a private key in as little as a week.

Drake’s concerns are not without merit; AI’s rapid progress in mathematical ability is plain to see. In May this year, OpenAI announced that AI had found a counterexample to the Erdős unit distance conjecture. In August, it revealed progress on a batch of long-standing open problems. In September, it announced that an internal model had solved the Navier–Stokes Millennium Prize Problem. And now, it has publicly released hundreds of mathematical research results at once…

In his call to action, Drake said we may be at a turning point where “centuries of mathematical progress happen in a matter of weeks.” If AI can challenge long-held human assumptions about the difficulty of mathematical problems in an extremely short time, then the problems in cryptography that “we currently consider hard enough” may also have shortcuts that have yet to be discovered.

ECDSA is particularly dangerous because it has a very rich mathematical structure. Tools ranging from Schoof’s algorithm and Frobenius to pairings are built on these structures, while one of the design goals of cryptographic hash functions is precisely to minimize exploitable mathematical structure. The richer the structure, the more “shortcuts” may theoretically exist that have yet to be discovered.

Drake therefore proposed a rather extreme scenario, but one he believes is worth preparing for in advance. In the future, AI could find a classical algorithm similar to Shor’s algorithm, allowing attackers to quickly derive private keys from public information without relying on a quantum computer. If that happens, assets protected by ECDSA could be directly exposed.

Against this backdrop, Drake proposed what he calls “bunker mode.” For ordinary holders, the core recommendation is to gradually move assets to new addresses that have never initiated a transaction. The reason is that the public keys of such addresses have not yet been directly exposed on-chain; the addresses themselves have only been hashed. Once an address signs a transaction, however, its public key may be revealed. If a new type of attack against ECDSA emerges in the future, attackers would theoretically have more information to exploit. For key signers such as exchanges, custodians, oracles, and L2 security councils, he offered more aggressive recommendations, including strengthening cold-wallet security, regularly rotating ECDSA public keys, and even adopting hash-based signature schemes for multisignatures where possible.

Drake stressed that this process should happen “slowly”: don’t panic, and don’t rush into a mass migration, because migration itself creates new operational risks. In particular, addresses holding fewer than 50 BTC may enjoy a degree of implicit protection from the “Satoshi shield”—the 20,000 addresses associated with Satoshi, each holding 50 BTC and with their public keys already exposed.

Drake concluded by saying that to safely exit bunker mode in the future, the industry will need “post-AI cryptography” capable of withstanding the AI era. He recommends going all in on hash-based cryptography and avoiding any structured mathematical assumptions entirely, because whenever a system depends on some complex mathematical structure, we should assume AI may find a new way to attack it in the future.

Vitalik’s stance: moving funds is fine, but don’t rush

Following Drake’s warning, Ethereum co-founder Vitalik Buterin also shared his views on the matter.

Compared with Drake’s aggressive warning, Vitalik’s stance is clearly more restrained. He first made clear that he agrees people should keep their funds in brand-new addresses that have never signed a transaction, provided this is not operationally cumbersome. But he does not recommend that anyone rush to move assets today because of AI-driven mathematical breakthroughs: migrating keys itself carries operational risks, and a mistake during migration could cause even greater losses than a hacker attack.

But this does not mean Vitalik thinks the risk can be ignored. Quite the opposite: Vitalik believes the industry should seriously consider a possibility that has not previously been fully incorporated into risk models—not only could elliptic curves be disrupted by AI-accelerated mathematics, but the “post-quantum cryptography” that the future is counting on may not be entirely safe either.

Vitalik specifically named ML-DSA, FHE, and lattice-based cryptography. The industry has generally believed that quantum computing would primarily threaten elliptic curves and RSA, while schemes such as lattice-based cryptography could serve as the next generation of secure foundations. But Vitalik believes that under the assumption that AI accelerates mathematics, this distinction may not be so robust.

Vitalik’s explanation is that history is full of similar cases: a problem is thought to require an extremely high level of computational complexity, but after decades of study, mathematicians discover a hidden structure that dramatically reduces the difficulty of solving it. If AI can compress decades of human mathematical exploration into a few years or even months, then lattice-based cryptography could also contain shortcuts that have yet to be discovered.

Like Drake, Vitalik is more optimistic about pure-hash cryptography. In his view, schemes such as elliptic curves and lattice-based cryptography are built on specific mathematical structures, whereas hash functions are designed precisely to avoid exploitable structures as much as possible. If AI’s advantage lies in discovering hidden mathematical structures, then a cryptographic system with “no structure to discover” is clearly more deserving of trust.

Pure-hash cryptography, however, cannot solve every problem once and for all. Signatures and proofs can be switched entirely to pure hashes, but the real impasse is public-key encryption (PKE)—which underpins secure website access, encrypted communications, VPNs, and the security of the entire internet. Mathematical theorems have long established that hash functions with no algebraic structure cannot, by themselves, be used to construct a public-key encryption system. To build one, we must introduce mathematical structures with trapdoors. And as long as such structures exist, we must assume AI could make breakthroughs against them. Faced with this reality, Vitalik’s advice is that if we want a lattice-based encryption system to remain theoretically secure over the long term, the simplest solution is to increase the parameter and key sizes tenfold.

As for Vitalik’s operational recommendations, in addition to advising users not to rush to move their funds, he offered two defensive strategies for on-chain applications. First, privacy protocols should avoid hard-coding encrypted notes directly on-chain and instead use off-chain third-party channels as much as possible. Second, multisig wallets should prioritize completing signature approval off-chain, so signers’ public keys are not exposed to the entire network prematurely. That way, even if the underlying ECDSA suffers an irreversible mathematical blow, the multisig system would merely “gracefully degrade” into a single-signature mode controlled by the signature collector—at least a better outcome than the disaster of leaving the doors wide open and allowing anyone to withdraw funds at will.

In the AI era, are the industry’s security foundations still solid?

Whether it is Justin Drake, advocating extreme defenses, or Vitalik Buterin, who takes a more engineering-focused and pragmatic view, the warnings issued in quick succession by these two leading minds of Ethereum pose a more profound philosophical question to the entire crypto world: as AI begins to lead mathematical research, are the foundations on which the industry relies really solid?

For more than a decade, “In Math We Trust” has been a foundational emblem of the belief in decentralization. We have grown accustomed to trusting elegant, complex algebraic structures as a solid refuge, pushing the risk of unknown breakthroughs off to the distant future. But OpenAI’s progress on hundreds of mathematical conjectures has starkly revealed a fact: what seems “unbreakable” to us may only seem that way because our own computational power moves too slowly through the mathematical maze.

When AI starts traversing centuries of mathematical progress in a matter of weeks, the balance between attack and defense has already shifted. Future defenses may have to embrace a kind of minimalist “back-to-basics” approach, retreating from a reliance on complex, elegant structures to the structureless simplicity of pure-hash cryptography.

This may be the first true head-on collision between blockchain and artificial intelligence at the level of foundational security. For ordinary people caught up in it, there is no need to panic and lose your head, but it is time to abandon blind faith in static security. In this new cycle ushered in by mathematical superintelligence, staying clear-eyed and respecting the unknown attack surface is the best “bunker” for protecting on-chain wealth.